GRC Risk & Compliance Analyst

Massachusetts Bay Transportation Authority

Boston (MA)

On-site

USD 90,000 - 120,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

The Massachusetts Bay Transportation Authority is seeking a Governance, Risk, and Compliance Analyst to identify, assess, monitor, and mitigate organizational risks while ensuring regulatory and internal policy alignment. This role collaborates with IT, cybersecurity, audit, and leadership to strengthen MBTA's GRC framework.

In Enterprise & Information Security Risk Management, you will perform risk assessments across IT, OT, and business processes, maintain the risk register, and help mature

Qualifications

  • Bachelor’s degree in a related field and 2 years of relevant experience.
  • Experience performing risk assessments and documenting findings.
  • Familiarity with risk management methodologies and control frameworks.
  • Knowledge of regulatory standards (NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, SOX).

Responsibilities

  • Conduct enterprise and information security risk assessments across IT, OT, and business processes.
  • Maintain and update the MBTA risk register and remediation actions.
  • Monitor compliance with ISO 27001, NIST CSF/800-53, PCI DSS, and other MBTA mandates.
  • Support audits and provide evidence collection.
  • Develop risk dashboards and executive summaries.

Skills

Analytical skills
Cross-functional collaboration
Regulatory knowledge
Documentation

Education

Bachelor's degree in IT / Cybersecurity / Information Systems / Business / Finance / Risk Management

Job description

The Massachusetts Bay Transportation Authority is seeking a Governance, Risk, and Compliance Analyst to identify, assess, monitor, and mitigate organizational risks while ensuring regulatory and internal policy alignment. This role collaborates with IT, cybersecurity, audit, and leadership to strengthen MBTA's GRC framework.

In Enterprise & Information Security Risk Management, you will perform risk assessments across IT, OT, and business processes, maintain the risk register, and help mature

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Risk & Compliance Analyst
GRC Risk & Compliance Analyst

Massachusetts-Bay-Transportation-Authority • Boston (MA)

On-site
USD 85,000 - 120,000
GRC Analyst
GRC Analyst

Massachusetts Bay Transportation Authority • Boston (MA)

On-site
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

Massachusetts-Bay-Transportation-Authority • Boston (MA)

On-site
USD 85,000 - 120,000
GRC Analyst: Risk, Audit & BC/DR (Hybrid MA)
GRC Analyst: Risk, Audit & BC/DR (Hybrid MA)

Kayak • United States

Hybrid
USD 85,000 - 95,000
Hybrid work flexibility
Mental health focus
Parental leave
+7
GRC Risk & Compliance Manager | Equity & Impact
GRC Risk & Compliance Manager | Equity & Impact

WHOOP • Boston (MA)

On-site
USD 155,000 - 195,000
Cyber Risk & Compliance Analyst — Hybrid/Remote
Cyber Risk & Compliance Analyst — Hybrid/Remote

Boston Government Services, LLC (BGS) • Knoxville (TN)

Hybrid
USD 136,000 - 161,000
Health Insurance
Dental Insurance
Vision Insurance
+4
Senior GRC Leader — Tech & AI Compliance
Senior GRC Leader — Tech & AI Compliance

Tacony Corporation • St. Louis (MO), Northern (KY)

Hybrid
USD 120,000 - 190,000
Health and Life Insurance Plans
Dental and Vision Plans
401(k) with company match
+6
Senior Cybersecurity Risk & GRC Leader
Senior Cybersecurity Risk & GRC Leader

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
IT Risk & Controls Analyst - Governance & Compliance
IT Risk & Controls Analyst - Governance & Compliance

BMA Group Global • Carolina (PR)

On-site
USD 80,000 - 110,000
GRC Analyst
GRC Analyst

American Tower Global • Boston (MA)

On-site
USD 85,000 - 120,000